Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security vulnerability: one router for public and private routes #15

Closed
aichbauer opened this issue Apr 25, 2018 · 0 comments
Closed

Security vulnerability: one router for public and private routes #15

aichbauer opened this issue Apr 25, 2018 · 0 comments

Comments

@aichbauer
Copy link
Owner

Security vulnerability

PLEASE UPDATE YOUR PACKAGE TO v1.0.2

Special thanks to @alvaroqt who found this vulnerability, and reported it to me.

Private routes accessible on public routes and vice versa.

Every version up to v1.0.1 has a security vulnerability and is not save for production. PLEASE UPDATE YOUR PACKAGE TO v1.0.2

In versions up to v.1.0.1 only one router gets instantiated. Which means every public route is available on private routes and vice versa.

If you update your version to v1.0.2 every known security vulnerability is fixed and you are ready to use it as is. There are NO breaking changes in the current API, so you don't have to change anything in your code, except updating your current version of express-routes-mapper to v1.0.2.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant